cleantalk
Vulnerabilities and Security Researches

Avatar, CVE-2025-39434

CVE, Research URL

CVE-2025-39434

Application

Avatar

Published on
Apr 17, 2025
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Avatar: from n/a through 0.1.4.
Affected versions
max 0.1.4.
Status
vulnerable